Junglewise Threat Intelligence

CVE-2026-65641: Veeam ONE SMB authentication coercion

CVE-2026-65641 · Severity: info · CVSS 9.3 · Published 2026-08-26

Executive brief

Veeam ONE is a monitoring and management platform used to oversee backup and virtualization infrastructure. An unauthenticated attacker on the network can force the service account to authenticate via SMB, potentially leading to credential theft or lateral movement attacks. This vulnerability affects Veeam ONE version 13 and has been rated critical due to the ability to compromise service account credentials.

Technical details

This vulnerability allows an unauthenticated network attacker to coerce SMB authentication from Veeam ONE's service account, a form of credential exfiltration attack (similar to NTLM relay or responder-style attacks). The attack requires only network reachability to the affected service with no authentication or user interaction required. The vulnerable component accepts and processes SMB authentication requests from unauthenticated sources, allowing attackers to extract service account credentials or perform relay attacks. Affected versions are Veeam ONE 13.1.0.7034 and earlier 13.x builds; versions 12.x and earlier are not affected. Patches are available: Veeam ONE 13.1 Patch 0 (build 13.1.0.7233) and Veeam ONE 13.0.2 Patch 1 (build 13.0.2.7159).

Affected products

  • Veeam ONE 13.1.0.7034 and earlier 13.x builds

Timeline

  • 2026-08-26: disclosed
  • 2026-08-25: patched: Veeam ONE 13.1 Patch 0 (build 13.1.0.7233) and Veeam ONE 13.0.2 Patch 1 (build 13.0.2.7159)
  • 2026-08-25: other: Vulnerability reported through HackerOne

References